Skip to content
Noroxi

Rocket.Chat records

64 published records for vendor rocket.chat.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
18.8%
Median publish → KEV
No record has entered KEV

All records

64 records
  • CVE-2021-22911
    68This week

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio

    CriticalCVSS 9.8Proof of conceptEPSS 95%

    rocket.chat · rocket.chatMay 27, 2021

  • A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could

    CriticalCVSS 9.8No exploitEPSS 2%

    rocket.chat · rocket.chatAug 9, 2021

  • Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

    CriticalCVSS 9.8No exploitEPSS 2%

    rocket.chat · rocket.chatJan 2, 2018

  • A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternal

    CriticalCVSS 9.8No exploitEPSS 2%

    rocket.chat · rocket.chatDec 23, 2022

  • Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML

    CriticalCVSS 9.8No exploitEPSS 2%

    rocket.chat · rocket.chatDec 30, 2020

  • A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not i

    CriticalCVSS 9.8No exploitEPSS 1%

    rocket.chat · rocket.chatMay 9, 2023

  • In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account t

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    rocket.chat · rocket.chatApr 22, 2026

  • Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did n

    CriticalCVSS 9.8No exploitEPSS 0%

    rocket.chat · rocket.chatJul 30, 2026

  • Rocket.Chat: Users can login with any password via the EE ddp-streamer-service

    CriticalCVSS 9.3No exploitEPSS 1%

    rocket.chat · rocket.chatMar 6, 2026

  • Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.

    CriticalCVSS 9.3No exploitEPSS 0%

    rocket.chat · rocket.chatJun 17, 2026

  • A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

    HighCVSS 8.6Proof of conceptEPSS 3%

    rocket.chat · rocket.chatAug 5, 2024

  • A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasse

    HighCVSS 8.8No exploitEPSS 1%

    rocket.chat · rocket.chatSep 23, 2022

  • A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password t

    HighCVSS 8.8No exploitEPSS 1%

    rocket.chat · rocket.chatSep 23, 2022

  • A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.

    HighCVSS 8.8No exploitEPSS 1%

    rocket.chat · rocket.chatFeb 23, 2023

  • Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer

    HighCVSS 8.0No exploitEPSS 1%

    rocket.chat · rocket.chatMar 6, 2026

  • An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be d

    HighCVSS 7.5No exploitEPSS 2%

    rocket.chat · rocket.chatMay 27, 2021

  • Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion

    HighCVSS 7.5No exploitEPSS 1%

    rocket.chat · rocket.chatJun 17, 2026

  • The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.

    HighCVSS 7.5No exploitEPSS 1%

    rocket.chat · rocket.chatJul 5, 2021

  • A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to ente

    HighCVSS 7.5No exploitEPSS 1%

    rocket.chat · rocket.chatMay 11, 2023

  • Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).

    HighCVSS 7.5No exploitEPSS 1%

    rocket.chat · rocket.chatSep 24, 2024

  • Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/live

    HighCVSS 7.5No exploitEPSS 0%

    rocket.chat · rocket.chatAug 21, 2026

  • CVE-2025-7974
    30Monitor

    rocket.chat Incorrect Authorization Information Disclosure Vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    rocket.chat · rocket.chatSep 2, 2025

  • An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a use

    HighCVSS 7.5No exploitEPSS 0%

    rocket.chat · rocket.chatMar 10, 2023

  • An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a m

    MediumCVSS 6.8No exploitEPSS 1%

    rocket.chat · rocket.chatSep 23, 2022

  • Rocket.Chat: NoSQL injection in the EE ddp-streamer-service

    MediumCVSS 6.9No exploitEPSS 0%

    rocket.chat · rocket.chatMar 6, 2026